My Home NW Lab

逸般の誤家庭のネットワーク

Catalyst 9800におけるPrimed Join Timeoutの挙動とPrimed Controllerとは何か

Catalyst 9800のAP Join Profileには「Primed Join Timeout」と呼ばれる設定項目があり、「Primed ControllerのTimeout値」を指定できます。

Primed Join TimeoutのWebの設定画面

  • まず「Primed Controller」とは、無線APに設定されているPrimary/Secondary/Tertiary WLCを指します。(DHCP Option 43やDNSで学習したControllerの情報は含まれません。)

  • そして無線APは「Primed Join Timeout」の期間は、Primed Controllerに接続できなくても諦めずに何度もJoinを試みます。

  • 言い方を変えると、Primed Join Timeoutの期間は「Primed Controller以外の別のWLC (Non Primed Controller)」を無視する時間です。

「代表的な無線APのJoinの制御方法」と「Primed Controller」

Primed Join Timeoutが関わる具体的なシナリオ

機能の挙動だけでは伝わりにくいため、具体的なシナリオで解説します。

一例として、無線APがWLCの情報を下記のように学習している環境があるとします。

  • Primary WLC: wlc01
  • Secondary WLC: wlc02
  • Tertiary WLC: wlc03
  • DHCP Option 43: wlc04
  • DNS: wlc05

無線APがWLCへの接続が出来なくなった際に、Primary/Secondary/Tertiary WLCである「wlc01, wlc02, wlc03」に「Primed Join Timeout」の期間/時間は継続的にJoinを試みます。

「Primed Join Timeout」(デフォルト値: 0 秒)を経過すると、DHCP Option 43やDNSで学習したWLCである「wlc04, wlc05」にJoinを試みます。

要は、「明示的な優先度が指定されているPrimed Controller」に優先してJoinを試みようとする期間/時間です。

設計の観点

無線APのJoin先のWLCは明示的に制御するため、Primary/Secondary/Tertiary WLCを明示的に指定するのが一般的です。

より細かな話をすると、DHCP Option 43でいずれかのWLCにJoinさせた後でも、AP Primingと呼ばれる機能でPrimary/Secondary/Tertiary WLCを効率的に設定するケースはあります。

結果的にDHCP Option 43やDNSから「Primed Controller以外の別のWLC」が参照されることがなく、Primed Join Timeoutが参照される機会が少なくなります。そのため、多くの環境ではPrimed Join Timeoutの設定値による影響を受ける機会は少ないと考えられます。

Primed Join Timeoutのログ

Primed Controllerで障害を発生させて、無線APをPrimed Join Timeoutのカウント ダウンが発生した際のログです。

ログの「Primed Timer Started. AP will only try to join Primary/Secondary/Tertiary for next 120 seconds」からカウント ダウンが発生しています。

ログから見るPrimed Join Timeoutの挙動

AP#[*01/12/2026 09:09:47.1847] Re-Tx Count=1, Max Re-Tx Value=5, SendSeqNum=85, NumofPendingMsgs=1
[*01/12/2026 09:09:47.1847]
[*01/12/2026 09:09:50.1865] Re-Tx Count=2, Max Re-Tx Value=5, SendSeqNum=91, NumofPendingMsgs=7
[*01/12/2026 09:09:50.1865]
[*01/12/2026 09:09:53.1879] Re-Tx Count=3, Max Re-Tx Value=5, SendSeqNum=91, NumofPendingMsgs=7
[*01/12/2026 09:09:53.1880]
[*01/12/2026 09:09:56.1895] Re-Tx Count=4, Max Re-Tx Value=5, SendSeqNum=91, NumofPendingMsgs=7
[*01/12/2026 09:09:56.1895]
[*01/12/2026 09:09:59.1911] Re-Tx Count=5, Max Re-Tx Value=5, SendSeqNum=91, NumofPendingMsgs=7
[*01/12/2026 09:09:59.1911]
[*01/12/2026 09:10:02.1922] Max retransmission count exceeded, going back to DISCOVER mode.
[*01/12/2026 09:10:02.1922] Dropping msg CAPWAP_ECHO_REQUEST, type = 1, len = 0, eleLen = 8, sendSeqNum = 91
[*01/12/2026 09:10:02.1923] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 14, eleLen = 22, sendSeqNum = 91
[*01/12/2026 09:10:02.1923] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 24, eleLen = 32, sendSeqNum = 91
[*01/12/2026 09:10:02.1923] ....TLV: TLV_RRM_LOAD_DATA_EXTENSION_PAYLOAD(4436), level: 0, seq: 0, nested: true
[*01/12/2026 09:10:02.1923] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 14, eleLen = 22, sendSeqNum = 91
[*01/12/2026 09:10:02.1924] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 24, eleLen = 32, sendSeqNum = 91
[*01/12/2026 09:10:02.1924] ....TLV: TLV_RRM_LOAD_DATA_EXTENSION_PAYLOAD(4436), level: 0, seq: 0, nested: true
[*01/12/2026 09:10:02.1924] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 14, eleLen = 22, sendSeqNum = 91
[*01/12/2026 09:10:02.1925] Dropping msg CAPWAP_WTP_EVENT_REQUEST, type = 34, len = 24, eleLen = 32, sendSeqNum = 91
[*01/12/2026 09:10:02.1925] ....TLV: TLV_RRM_LOAD_DATA_EXTENSION_PAYLOAD(4436), level: 0, seq: 0, nested: true
[*01/12/2026 09:10:02.1933] Flexconnect Switching to Standalone Mode!
[*01/12/2026 09:10:02.2410] wlan: [0:I:CMN_MLME] mlme_ext_vap_down: VAP (apr0v1) is down
[*01/12/2026 09:10:02.2635] wlan: [0:I:CMN_MLME] mlme_ext_vap_down: VAP (apr1v1) is down
[*01/12/2026 09:10:02.4790] GOING BACK TO DISCOVER MODE
[*01/12/2026 09:10:02.6019]
[*01/12/2026 09:10:02.6019] CAPWAP State: DTLS Teardown
[*01/12/2026 09:10:02.6694] CLEANAIR: Slot 0 CAPWAP down
[*01/12/2026 09:10:02.6704] CLEANAIR: Slot 2 CAPWAP down
[*01/12/2026 09:10:02.9566] status 'upgrade.sh: Script called with args:[CANCEL]'
[*01/12/2026 09:10:03.0235] do CANCEL, part2 is active part
[*01/12/2026 09:10:03.0789] status 'upgrade.sh: Cleanup tmp files ...'
[*01/12/2026 09:10:03.1528] Directory /tmp/ntevents not found.
[*01/12/2026 09:10:07.6931] dtls_queue_first: Nothing to extract!
[*01/12/2026 09:10:07.6931]
[*01/12/2026 09:10:07.6932] Primed Timer Started. AP will only try to join Primary/Secondary/Tertiary for next 120 seconds
[*01/12/2026 09:10:07.8099] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:07.8108] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:17.7989] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 110 seconds
[*01/12/2026 09:10:17.9107] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:17.9129] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:27.8034] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 100 seconds
[*01/12/2026 09:10:27.9339] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:27.9426] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:37.8281] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 90 seconds
[*01/12/2026 09:10:37.9768] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:37.9784] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:47.8117] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 80 seconds
[*01/12/2026 09:10:47.9441] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:47.9468] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:57.8157] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 70 seconds
[*01/12/2026 09:10:57.9458] Discovery Response from 198.51.100.242
[*01/12/2026 09:10:57.9515] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:07.8197] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 60 seconds
[*01/12/2026 09:11:07.9348] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:07.9376] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:17.8237] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 50 seconds
[*01/12/2026 09:11:17.9731] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:17.9774] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:27.8277] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 40 seconds
[*01/12/2026 09:11:27.9745] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:27.9762] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:37.8323] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 30 seconds
[*01/12/2026 09:11:37.9821] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:37.9852] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:47.8368] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 20 seconds
[*01/12/2026 09:11:47.9710] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:47.9780] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:57.8439] Discovery Responses received but not from primed controllers. Will restart discovery. AP will try joining the primed controllers for next 10 seconds
[*01/12/2026 09:11:57.9671] Discovery Response from 198.51.100.242
[*01/12/2026 09:11:57.9694] Discovery Response from 198.51.100.242
[*01/12/2026 09:12:08.0000] Started wait dtls timer (60 sec)
[*01/12/2026 09:12:08.0201]
[*01/12/2026 09:12:08.0201] CAPWAP State: DTLS Setup

関連情報

Cisco Catalyst 9800 Series Configuration Best Practices - Cisco
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html
Primary/secondary/tertiary versus backup primary/backup secondary」のセクションを参照

筆者が執筆中にドキュメントが更新されていたので、更新前後の内容を記載します。短めでシンプルで分かりやすい文章と、より詳細で誤解を招かないようにする文章のどちらも参考になるためです。

  • 2026年07月頃の情報

    Primed Join Timeout (sec): during this time the AP will only try to join the primed primary/secondary/tertiary controllers and will ignore discovery responses received from other controllers.

  • それ以前の情報

    Primed Join Timeout (sec): when the AP is in the controller discovery process, waiting on discovery responses from controller to decide which controller to join, the Primed Join Timeout applies. During the Primed Join Timeout the AP will only try to join the primed primary/secondary/tertiary controllers and will ignore discovery responses received from other controllers. The Primed Join Timeout is disabled by default.

関連記事

myhomenwlab.hatenablog.com

myhomenwlab.hatenablog.com

myhomenwlab.hatenablog.com

myhomenwlab.hatenablog.com

CiscoのWLC (AireOS)でコンフィグをターミナルから取得する

Cisco社のWLC (AireOS)にてコンフィグを保存したい場合は、「ターミナルに出力」する方法と、「ファイルとしてバックアップ」する方法があります。

まずファイルとしてバックアップする場合は、メニュー「COMMANDS > Upload File」の「Upload file from Controller」から行えます。

Web UIのUpload Fileのメニュー

注意: WLCの視点でのUpload方向になります。作業端末の視点から見てのDownloadと勘違いしないようにしてください。

AireOSでのコンフィグ取得イメージ (Web UI & ターミナル)

ただし、Webブラウザ経由で作業端末に直接のダウンロードはできません。TFTPサーバーなどに保存する必要があります。そのため、Cisco IOS系でいうところの「show running-config」のように、ターミナルから設定情報を取得したいケースが出てきます。

ターミナルからの取得コマンド

config paging disable

show run-config startup-commands

config paging enable

コンフィグの取得のためにPagerを一時的に無効化しています。

Pagerが有効化だと「--More-- or (q)uit」が表示されます。

Pagerの有効化時 (config paging enable)

活用例: AireOSからCatalyst 9800への移行時のコンフィグ比較

執筆時点の2026年06月現在では、AireOSからCatalyst 9800 (IOS-XEベース)へ移行する案件も増えてきています。移行プロジェクトでは、更改前後の設定差分を確認するために、AireOSのコンフィグを取得する機会があります。

その移行において、既存踏襲を容易にするためにCisco社からはWLC Config Converterのツールが提供されています。本記事で紹介した「show run-config startup-commands」からの読み込みに対応しています。ただし、全ての設定が変換対象として網羅されているわけではありません。

WLC Config Converter (AireOS, IOS-XE) - Cisco Community
https://community.cisco.com/t5/-/-/td-p/2895495

なお、既存踏襲はあくまでもサービス影響の軽減を達成するための一つの手段になります。

既存環境のパラメーターをすべて網羅的に比較・変換しようとすると多くの工数が必要になります。また無線LANは安定性を重視しつつ、最新規格の利点も享受したいケースがあります。そのため、リスク低減を落し所の一つとして、Best Practicesも踏まえて設計方針を検討し直す選択肢も考えられます。

Cisco Catalyst 9800 Series Configuration Best Practices - Cisco
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html

また、利用しない機能が明確化できれば、それに関連する個別パラメーターの調査コストを削減できる可能性もあります。例えば、既存のAireOSでmDNSを利用していなければ、更改後のCatalyst 9800でもmDNSをグローバルで無効化することで、関連するパラメーター (例: Service Policy) の設計やチューニングが不要になるかもしれません。

要点としては、プロジェクトには期間や工数の制約があるため、限られた時間で最大の効果が得られるよう判断することが重要です。

関連Issue

WLC で "show run-config startup-commands" 実行後に電源オフするとコンフィグが初期化される問題 - Cisco Community
https://community.cisco.com/t5/-/-/ta-p/4072102

出力例のサンプル

Version 8.10.190.0 での出力例です。

ログイン情報のようなセンシティブなものも含まれるので、Communityを活用してコンフィグをやり取りするようなケースではマスキングを適宜するようにしてください。

下記のログは SN (Serial Number)だけマスキングしています。

(Cisco Controller) >config paging disable


(Cisco Controller) >
(Cisco Controller) >
(Cisco Controller) >show run-config startup-commands

Config generation may take some time ...

# WLC Config Begin <Tue Jun  2 12:00:40 2026>
! Number of APs: 0
! Power Supply 1: Absent 
! Power Supply 2: Absent 
! PID: AIR-CTVM-K9,  SN: *********** 
! Product Version: 8.10.190.0 
! 
! ******************** PORT SUMMARY **********************
!  
!            STP   Admin   Physical   Physical   Link   Link
! Pr  Type   Stat   Mode     Mode      Status   Status  Trap     POE    
! -- ------- ---- ------- ---------- ---------- ------ ------- ---------
! 1  Normal  Forw Enable  Auto       1000 Full  Up     Enable  N/A     
! 
! ******************** CDP NEIGHBOUR SUMMARY **********************
! 
! Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
!                   S - Switch, H - Host, I - IGMP, r - Repeater, 
!                   M - Remotely Managed Device
! 
! Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID

config countries-list add J4  
config dhcp proxy disable bootp-broadcast disable 
config network multicast l2mcast disable service-port 
config network multicast l2mcast disable virtual 
config network rf-network-name WLC_GROUP 
config mdns profile create default-mdns-profile 
config mdns profile service add default-mdns-profile AirTunes 
config mdns profile service add default-mdns-profile Airplay 
config mdns profile service add default-mdns-profile Googlecast 
config mdns profile service add default-mdns-profile HP_Photosmart_Printer_1 
config mdns profile service add default-mdns-profile HP_Photosmart_Printer_2 
config mdns profile service add default-mdns-profile HomeSharing 
config mdns profile service add default-mdns-profile Printer-IPP 
config mdns profile service add default-mdns-profile Printer-IPPS 
config mdns profile service add default-mdns-profile Printer-LPD 
config mdns profile service add default-mdns-profile Printer-SOCKET 
config mdns profile service add default-mdns-profile iTuneWirelessDeviceSharing_2 
config mdns service origin all AirTunes 
config mdns service create AirTunes _raop._tcp.local. origin all lss disable 
config mdns service origin all Airplay 
config mdns service create Airplay _airplay._tcp.local. origin all lss disable 
config mdns service origin all Googlecast 
config mdns service create Googlecast _googlecast._tcp.local. origin all lss disable 
config mdns service origin all HP_Photosmart_Printer_1 
config mdns service query enable HP_Photosmart_Printer_1 
config mdns service create HP_Photosmart_Printer_1 _universal._sub._ipp._tcp.local. origin all lss disable query enable 
config mdns service origin all HP_Photosmart_Printer_2 
config mdns service query enable HP_Photosmart_Printer_2 
config mdns service create HP_Photosmart_Printer_2 _cups._sub._ipp._tcp.local. origin all lss disable query enable 
config mdns service origin all HomeSharing 
config mdns service query enable HomeSharing 
config mdns service create HomeSharing _home-sharing._tcp.local. origin all lss disable query enable 
config mdns service origin all Printer-IPP 
config mdns service create Printer-IPP _ipp._tcp.local. origin all lss disable 
config mdns service origin all Printer-IPPS 
config mdns service create Printer-IPPS _ipps._tcp.local. origin all lss disable 
config mdns service origin all Printer-LPD 
config mdns service create Printer-LPD _printer._tcp.local. origin all lss disable 
config mdns service origin all Printer-SOCKET 
config mdns service create Printer-SOCKET _pdl-datastream._tcp.local. origin all lss disable 
config mdns service origin all iTuneWirelessDeviceSharing_2 
config mdns service create iTuneWirelessDeviceSharing_2 _apple-mobdev2._tcp.local. origin all lss disable 
config advanced 802.11b packet silver max-client-count 0 
config advanced 802.11b packet silver max-packet-count 0 
config advanced 802.11b packet silver timeout 0 
config advanced 802.11b packet silver max-retry 0 
config advanced 802.11b packet platinum max-client-count 0 
config advanced 802.11b packet platinum max-packet-count 0 
config advanced 802.11b packet platinum timeout 0 
config advanced 802.11b packet platinum max-retry 0 
config advanced 802.11b packet gold max-client-count 0 
config advanced 802.11b packet gold max-packet-count 0 
config advanced 802.11b packet gold timeout 0 
config advanced 802.11b packet gold max-retry 0 
config advanced 802.11b packet bronze max-client-count 0 
config advanced 802.11b packet bronze max-packet-count 0 
config advanced 802.11b packet bronze timeout 0 
config advanced 802.11b packet bronze max-retry 0 
config advanced 802.11b channel add 1 
config advanced 802.11b channel add 6 
config advanced 802.11b channel add 11 
config advanced 802.11a packet silver max-client-count 0 
config advanced 802.11a packet silver max-packet-count 0 
config advanced 802.11a packet silver timeout 0 
config advanced 802.11a packet silver max-retry 0 
config advanced 802.11a packet platinum max-client-count 0 
config advanced 802.11a packet platinum max-packet-count 0 
config advanced 802.11a packet platinum timeout 0 
config advanced 802.11a packet platinum max-retry 0 
config advanced 802.11a packet gold max-client-count 0 
config advanced 802.11a packet gold max-packet-count 0 
config advanced 802.11a packet gold timeout 0 
config advanced 802.11a packet gold max-retry 0 
config advanced 802.11a packet bronze max-client-count 0 
config advanced 802.11a packet bronze max-packet-count 0 
config advanced 802.11a packet bronze timeout 0 
config advanced 802.11a packet bronze max-retry 0 
config advanced 802.11a channel add 36 
config advanced 802.11a channel add 40 
config advanced 802.11a channel add 44 
config advanced 802.11a channel add 48 
config advanced 802.11a channel add 52 
config advanced 802.11a channel add 56 
config advanced 802.11a channel add 60 
config advanced 802.11a channel add 64 
config advanced 802.11a channel add 100 
config advanced 802.11a channel add 104 
config advanced 802.11a channel add 108 
config advanced 802.11a channel add 112 
config advanced 802.11a channel add 116 
config advanced 802.11a channel add 120 
config advanced 802.11a channel add 124 
config advanced 802.11a channel add 128 
config advanced 802.11a channel add 132 
config advanced 802.11a channel add 136 
config advanced 802.11a channel add 140 
config advanced 802.11a channel add 144 
config advanced 802.11a channel add 184 
config advanced 802.11a channel add 188 
config advanced 802.11a channel add 192 
config advanced 802.11a channel add 196 
config wlan wmm allow 1 
config wlan mfp client enable 1 
config wlan mdns profile 1 none 
config wlan mdns disable 1 
config wlan dhcp-scope 1 scope-name none 
config wlan dms enable 1 
config wlan broadcast-ssid enable 1 
config wlan flexconnect local-switching 1 enable 
config wlan session-timeout 1 1800 
config wlan security wpa enable 1 
config wlan security ft adaptive enable 1 
config wlan security web-auth server-precedence 1 local radius ldap 
config wlan bss-transition enable 1 
config wlan interface 1 management 
config wlan assisted-roaming neighbor-list enable 1 
config wlan create 1 SSID_TEST SSID_TEST 
config wlan exclusionlist 1 180 
config wlan enable 1 
config mobility group mcpublicip 10.128.255.241 
config mobility group domain WLC_GROUP 
config sysname vwlc01 
config database size 2048 
config mgmtuser telnet admin enable 
config mgmtuser add encrypt admin 1 b2263b32b844dc2c96ab623614f0f856 6fbb94f8003d38b39781d81e046df065fa562c14 16 7c7384705a63cd630b3e5677eb9908f80000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 read-write 
config mgmtuser add encrypt_v1 admin 1 e87ab2c24aa25386f9fa9a1ed1096775 a1783d91479f33ba0de615efadea01f8e6378146 16 777d8dabf7f15b152cd4e1910244de1400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 read-write 
config switchconfig strong-pwd lockout attempts mgmtuser 3 
config switchconfig strong-pwd lockout time mgmtuser 5 
config 802.11a cac voice sip bandwidth 64 sample-interval 20 
config 802.11a cac voice sip codec g711 sample-interval 20 
config 802.11b 11gsupport enable 
config 802.11b cac voice sip bandwidth 64 sample-interval 20 
config 802.11b cac voice sip codec g711 sample-interval 20 
config interface address management 10.128.255.241 255.255.255.0 10.128.255.254 
config interface address service-port 10.128.254.241 255.255.255.0 
config interface address virtual 192.0.2.123 
config interface dhcp management primary 10.128.255.254 
config interface port management 1 
config interface dhcp service-port disable 
config snmp v3user delete default 
config snmp community delete public 
config snmp community delete private 
config ap antenna monitoring all weak-rssi 60 
config ap antenna monitoring all rssi-failure-threshold 40 
config ap antenna monitoring all detection-time 12 
config ap dtls-version dtls_all 
config ap mgmtuser add encrypt username admin password 1 2453e949bad7f15983f94b7a62078c15 e3407949d3103503ab4e702a108a839db6f0f58e 16 7eb194a4929ece301748b8b94e3bbffa0000000000000000000000000000000000000000000000000000000000000000 24312465754c32244a71454972362f585774515445636e71534850412e2f00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 secret encrypt 243124764c5734246b3943564859756635613948674d6649706f6231653100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 all 
config ap tcp-adjust-mss enable all 1250 
config ap packet-dump buffer-size 2048 
config ap packet-dump capture-time 10 
config ap packet-dump truncate 0 
config ap client-stats enable interval 90 
config ap preferred-mode ipv4 all 
config mesh convergence 
config country J4 
config remote-lan flexconnect local-switching 1 enable 
transfer download ap-images cco-password $password 
transfer download ap-images cco-username $username 

# WLC Config End <Tue Jun  2 12:00:41 2026>


(Cisco Controller) >
(Cisco Controller) >
(Cisco Controller) >config paging enable


(Cisco Controller) >
(Cisco Controller) >

関連ドキュメント

英語

Cisco Wireless Controller Command Reference, Release 8.10 - Show Commands: r to z [Cisco Wireless LAN Controller Software] - Cisco
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/cmd-ref/b-cr810/show_commands_r_to_z.html#wp2616355614

日本語翻訳

Version 8.5であれば日本語翻訳のドキュメントがあります。

Cisco Wireless Controller リリース 8.5 コマンド リファレンス - show コマンド:r ~ z [Cisco Wireless LAN Controller ソフトウェア] - Cisco
https://www.cisco.com/c/ja_jp/td/docs/wireless/controller/8-5/cmd-ref/b-cr85/b-cr85_chapter_010001.html#wp1612346419

Catalyst 9800で6 GHz有効時にWPA3 SAEのHunting and Pecking Onlyが指定できない

Catalyst 9800のSSID (WLAN Profile)にて、6 GHzの有効化時にWPA3 SAEで「Hunting and Pecking Only」は指定できません。

背景

まずWPA3のPWE (Password Element)の方式には、
1. Hunting and Pecking (HnP)
2. Hash to Element (H2E)
の2通りの方式があります。

6 GHz帯とWPA3 SAE

「Hunting and Pecking (HnP)」には、Dragonbloodと呼ばれるWPA3 SAEに対する攻撃手法において、タイミング攻撃やサイドチャネル攻撃の影響を受けやすい実装方式とされています。 Dragonbloodへの対策として、SAEに拡張が加えられ、よりセキュアな「Hash-to-Element (H2E)」が導入されました。

Wi-Fi 6EでWPA3 SAEを利用する際には、Wi-Fi AllianceのWPA3の認証要件によって、6 GHz帯では「Hash-to-Element (H2E)」が必須とされており、「Hunting and Pecking」は許可されていません。

Catalyst 9800で6 GHz有効時にWPA3 SAEのHunting and Pecking Onlyが指定できない

H2EとHnPの両方を許可する組み合わせもあるため、設定可否を表にすると下記の通りになります。

組み合わせ 設定可否 設計観点の備考
6 GHz & Both H2E and HnP OK 下位互換性の維持
6 GHz & Hash to Element Only OK セキュリティ的に推奨
6 GHz & Hunting and Pecking Only NG 6 GHz帯ではHnPが許可されていない & HnPは攻撃耐性が低い

2026年04月頃に最新の v17.18.2 の時点で、デフォルト値は「Both H2E and HnP」です。

設計の観点

互換性重視の「Both H2E and HnP」(デフォルト値)から、よりセキュアな「Hash to Element Only」に変更する場合は、端末の互換性への影響を考慮する必要があります。

  • 業務向けSSIDの場合は、接続端末が情報システム部門の管理下にあることが多いため、事前に検証することで互換性問題の影響の洗い出しができます。
  • しかしゲスト向けSSIDの場合は、不特定多数の端末が接続するため、すべての端末との互換性を保証することは困難です。そのため、サポート対象の端末の条件を明示するなど、提供条件で整理するのが現実案として考えられます。

6 GHz有効時にHnP Onlyを設定した場合のエラー

Web UIとCLIで設定時のエラーを掲載します。

Web UIでのエラー

Web UIから設定を試みると下記のようなエラーが表示されます。

Error in Configuring WLAN
Hunting and Pecking is not allowed with 6 GHz radio policy

Web UIでのエラー

CLIでのエラー

CLIから設定を試みると下記のようなエラーが表示されます。

wlc01(config)# wlan WLAN_OFFICE 98 OFFICE
wlc01(config-wlan)# shutdown
wlc01(config-wlan)# radio policy dot11 6ghz
wlc01(config-wlan)# security wpa akm sae pwe hnp
wlc01(config-wlan)# no shutdown
% node-1:dbm:wireless:Hunting and Pecking is not allowed with 6 GHz radio policy
wlc01(config-wlan)#

WPA3 Specification

WPA3の仕様書に「6 GHz帯での制約においてHunting and Peckingは許可されてない (shall not allow) 」旨が記載されています。

WPA3 Specification
https://www.wi-fi.org/file/wpa3-specification

最新版にリダイレクトされます。2026年04月時点の最新版はv3.5でした。

直接リンク: https://www.wi-fi.org/system/files/WPA3%20Specification%20v3.5.pdf

11.2 Constraints in the 6 GHz band

<~省略~>

When a WPA3 STA is connecting to an AP in the 6 GHz band:
a. The STA shall not allow: WEP, TKIP, any PSK (or FT PSK) AKM, 802.1X SHA-1 AKM, or the SAE Hunting and Pecking mechanism
b. The STA shall always negotiate PMF
c. The STA shall not allow Open System authentication without encryption

Ciscoの関連ドキュメント

Configure and Verify Wi-Fi 6E WLAN Layer 2 Security - Cisco https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/220712-configure-and-verify-wi-fi-6e-wlan-layer.html

SAE
WPA3 use a new authentication and key management mechanism called Simultaneous Authentication of Equals. This mechanism is further enhanced through the use of SAE Hash-to-Element (H2E).
SAE with H2E is mandatory for WPA3 and Wi-Fi 6E.

Communityの関連トピック

WPA3のセキュリティ周りの話は、Cisco社のWebinarで分かりやすく解説されています。

3/18 開催 Cisco 無線 LAN セキュリティの内部動作と検証 ― WPA3・802.1X・鍵管理と脅威対応の仕組み ― - Cisco Community
https://community.cisco.com/t5/-/-/ev-p/5370532

Cisco CW9172HのSerial Consoleポートの物理的な位置

Cisco CW9172HのSerial Consoleポートは、縦置き状態の正面から見て右側の側面にあり、カバーで塞がっています。RJ-45の端子のため、LANポートと混同しないように留意が必要です。

Cisco CW9172HのSerial Consoleポートの位置

カバー自体にはRJ-45端子のようなラッチ機構 (爪)は無いため、ポートに対して真っ直ぐ引くように抜けば取れます。

Cisco CW9172HのSerial Consoleポートのカバー

天井などの高所への設置後に、マウントされた状態でカバーを外すのは危険です。事前にカバーを外しておくかどうかを関係者間で取り決めておくことを推奨します。

情報源

Hardware Installation Guideに記載があります。

Cisco Wireless 9172H Series Wi-Fi 7 Access Point Hardware Installation Guide - Hardware Features [Cisco Catalyst 9100 Access Points] - Cisco
https://www.cisco.com/c/en/us/td/docs/wireless/access_point/cw917x/cw9172h/b-hig-cw9172h/hardware-features.html

RJ-45 console port with cover

製品写真に関して

製品写真はBrand Exchangeから入手できるため、キッティングの手順書などに必要であれば、好みのものを入手してください。

myhomenwlab.hatenablog.com

関連記事

myhomenwlab.hatenablog.com

Catalyst 9800のWMIへの管理接続を制御する (Management via Wireless)

Catalyst 9800において、SSID (Wireless)からの接続を介したWMIへの管理接続 (ping, ssh, https)は「Management via Wireless」から制御可能です。

Management via Wirelessでの制御のイメージ

Management via Wireless SSID経由のWMIへの通信の可否
Disabled (Default) × NG
Enabled ○ OK
  • WMI (Wireless Management Interface)が制御対象です。
  • 物理版のGi0 (vrf Mgmt-intf)は制御対象ではありません。
  • 「via Wireless」の名称の通りに、SSID (Wireless)を介した管理通信に作用します。
  • 有線 (Wired)からWMIへの管理通信には作用しません。
  • 「Management Via Wireless」はデフォルトで無効化されています。

設計の観点

  • 特にゲスト向けのSSIDのような「不特定多数の端末の接続」が想定される場合は、WMIに対する管理接続が行われないように無効化を検討する必要があります。また、社内向けのSSIDしか提供していない場合でも、社員が勝手にWLCに接続できないようにする観点があります。

  • Catalyst 9800への設定変更をSSID (Wireless)経由で行うと、設定ミスした際にSSID自体にアクセスできなくなる可能性があるため、作業端末は有線 (Wired)経由でアクセスできるようにするのが好ましいです。

注意点

FlexConnect modeのLocal Switchingにおいて、WMIと端末の所属VLAN/セグメントが同じ場合は、CSCvu29200 の影響でWMIへの管理接続ができません。

Management via Wirelessにおける CSCvu29200 の影響

Cisco Bug: CSCvu29200 - mgmt-via-wireless not working if client has IP from wireless mgmt vlan [ Flex local switching ]
https://quickview.cloudapps.cisco.com/quickview/bug/CSCvu29200

Symptom:
Flexconnect local switching wireless client will not be able to ping / ssh / https to the wireless controller if it has an ip from the controller's wireless management interface. If it gets an IP from another interface, everything works fine

Conditions:
Flexconnect / local switching
Client has IP from wireless management VLAN

Workaround:
use wired device or wireless client from another vlan to manage WLC

Further Problem Description:

CSCvu29200 の該当有無

Local Switchingの典型的なユースケースでは、拠点内で通信が完結する「端末から拠点内にあるプリンターへの通信」のようなユースケースに対して、Data Center折り返しが発生させたくない場合に採用されます。そのため、WLCと端末が同一セグメントになる設計は少なくなり、CSCvu29200 の条件を満たす可能性は低くなると想定されます。

設計の視点での CSCvu29200 の影響

ただし、機材が限られる検証環境だと、WLCと端末が同一セグメントになる可能性はあるので留意は必要です。

本事象は検証時点のv17.18.2で再現しており、2026年04月時点で修正バージョンは公開されていません。

設定方法

Web UI

メニュー「Configuration > Wireless > Wireless Global」の「Management Via Wireless」に設定項目があります。

Web UIからのManagement via Wirelessの設定

動作確認後は、設定の保存を忘れないようにしてください。

CLI

CLIから有効化 (Enabled)にする場合は、下記のコマンドを実行します。

configure terminal

wireless mgmt-via-wireless

end

動作確認後は、設定の保存 (write memory)を忘れないようにしてください。

関連ドキュメント

英語と日本語翻訳の両方ある v17.15.x 系のドキュメントのリンクを掲載します。

英語

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 17.15.x - Management over Wireless [Cisco Catalyst 9800 Series Wireless Controllers] - Cisco
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-15/config-guide/b_wl_17_15_cg/m_mgmt-over-wireless.html

日本語翻訳

Cisco Catalyst 9800 シリーズ ワイヤレス コントローラ(Cisco IOS XE 17.15.x)ソフトウェア コンフィギュレーション ガイド - ワイヤレスによる管理 [Cisco Catalyst 9800 シリーズ ワイヤレス コントローラ] - Cisco
https://www.cisco.com/c/ja_jp/td/docs/wireless/controller/9800/17-15/config-guide/b_wl_17_15_cg/m_mgmt-over-wireless.html

【備忘録】NW機器などのITインフラ製品で個人購入が不可だったもの

個人購入のあくなき挑戦を備忘録的に書き残します。

前書き

当たり前の話ではありますが、個人の検証用途で、NW機器などの業務向けのITインフラ製品を新品で購入するのはハードルが高いです。とは言っても、キャッチアップするには実機があるのが近道であり、個人での検証機の調達を試みる方はいらっしゃると思うので、参考程度に試行錯誤した情報を書き残します。

時間の経過とともに状況が変わる可能性がある点は留意してください。

謝辞

個人購入での問い合わせに応じてくださったご担当者様に感謝申し上げます。

個人購入できない要素

代表的な「個人購入できない要素」をまず紹介します。

  • メーカー側が個人購入を想定していないので、代理店を問わずに購入できない。

  • 個人購入に縛りはないが、代理店が個人との取引をしていない。

  • 個人購入のやり取りが可能な代理店であっても、その代理店がパートナーではないため製品を取り扱っていない。

  • 個人購入に縛りはないが、通販サイトで製品の在庫が無くなったり、取り扱いがなくなっている。

  • 海外の代理店で購入した話をコミュニティで見かけるものの、日本からの現実的な購入ルートが限られる。
    個人輸入向けの転送サービスなどを活用しようにも、現地の電話番号や、保守契約のための住所登録の側面で購入まで進めない。

海外からの取り寄せに関して

国内の代理店で製品を扱っていない場合でも、海外に視野を広げると入手経路がある可能性があります。

しかしながら、海外から購入する場合は、国が異なる故のトラブルに発展する可能性があるので。決済手段に選択肢があるのであれば、トラブルになった時の円滑な解決のために、「問題解決センターがあるPayPal」を利用するのがリスクが低くなると筆者は考えています。

Cisco Umbrella

2022年頃の時点で、代理店を問わずに、個人での購入が不可になっているようでした。

Cisco Cisco+ Secure Connect

2024年頃の時点で、代理店を問わずに、個人での購入が不可になっているようでした。

Juniper Mist AP

2020年以前にInteropでJuniperの担当者に話を伺ったところ、個人での購入に対して制限はかけていないものの、個人に卸してくれる代理店が見つかりませんでした。

また無線APは電波規制を受けるため、仮に国外から輸入する際は、電波暗室での利用の考慮などが必要になります。

HPE Aruba Networking Central

2019年頃の時点で、国内代理店経由での個人購入は不可でした。

より厳密には、筆者は(事業者と思われてしまったようで)個人購入は一度通ってしまいましたが、実際は個人購入が不可だったそうです。

また海外であれば、Hummingbird Networks社からライセンスの購入は可能でした。

Hummingbird Networks IT and Network Equipment Experts
https://www.hummingbirdnetworks.com/

Hummingbird Networks社の通販サイトは、日本からのアクセスが遮断されていた時期もありました。そのため、物理機器は国内で購入後して、Hummingbird Networks社でライセンスだけ追加で買うような計画を進めるのはリスクがあります。

Palo Alto Network PA

2020年の時点で、個人での購入が不可でした。

Palo Alto Network社の本国でエンドユーザー登録が行われるため、海外の代理店などを経由しても購入できないようです。

F5 Networks BIG-IP Virtual Edition Lab License

個人自体は購入可能です。ただし、「個人購入が可能な代理店経由」で購入する必要があり、在庫にも依存します。

筆者はOCN オンラインショップ (旧NTT-X Store)から購入した経験がありますが、時期によっては在庫がなかったです。

F5 Networks BIG-IP Virtual Edition Lab License (LTM、DNS、AFM、ASM、APM Lite、AAM、CGN、SSL Forward Proxy、Advanced Protocols、Crypto Offload、10 Mbps、v12.1.x - v18.x) F5-BIG-VE-LAB-V18 - NTT-X Store

Cisco Wi-Fi 7 APの「-CFG」と「-RTG」の型番の違い

Cisco Wi-Fi 7 AP (CW917x)の型番には、「CW9176I-CFG」や「CW9176I-RTG」のように、末尾に「-CFG」や「-RTG」と付くものがあります。

  • CFG」は「Configurable」の意味合いです。オプション類を詳細に選択可能です。

  • RTG」は「Ready to Go」の意味合いです。オプションが固定になりますが、比較的に短納期となる利点があります。

実際の違いを体験するには、Cisco Commerce Workspace (CCW) で見積もりの作成を試すのが分かりやすいです。CCW自体はCisco.comアカウントがあれば、パートナーでなくても操作できます。(2026年04月時点)

CFG (Configurable)型番

CFG (Configurable)型番

RTG (Ready to Go)型番

RTG (Ready to Go)型番

関連ドキュメント

Cisco Wireless Ordering Guide - Cisco
https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/nb-06-wrles-dna-sub-lic-og-cte-en.html

RTG: Ready to go – fastest shipment with default choices
CFG: Configurable – customizable accessories and packaging
● Special Handling (CFG++) – use for TAA compliant orders